Video summary
The Linux Foundation webinar titled "LF Live Webinar: The Cap(AI)bility Edge" challenges prevailing narratives that artificial intelligence will replace human workers, presenting data from the *2026 State of Tech Talent Report* which indicates that AI acts as a net driver for IT job creation with a +31% global hiring effect. While large organizations have seen minor negative impacts, the primary challenge facing the industry is not a shortage of roles but a significant capability gap affecting 57% of companies, particularly in deploying AI safely and securely across their entire technology stack. The discussion highlights that while headlines focus on layoffs at major tech firms, smaller companies are actively hiring to support growing AI infrastructure needs, with entry-level positions increasing globally despite regional variations in Europe and Japan.
Central to the argument is the necessity of upskilling existing workforces rather than replacing experienced employees, as their institutional wisdom and craft remain the true assets that tools like PowerPoint or Kubernetes cannot replicate. Experts emphasize that security concerns have become the number one barrier to AI adoption due to the "lethal trifecta" of risks involving agents with external browsing, database access, and communication capabilities, which traditional deterministic security models cannot adequately address. To bridge this gap, organizations are advised to retain their experienced staff and teach them how to manage non-deterministic AI workflows, rather than seeking short-term solutions by hiring new specialists who lack the necessary business context to guide these advanced tools effectively.
Beyond technical skills, the webinar underscores that foundational education remains essential for navigating the AI era, as degrees provide critical soft skills like communication and conflict resolution alongside a broader perspective needed to leverage AI productively. The speakers warn against the "pixie dust fallacy" of adopting AI without clear strategic goals, noting that while user expectations are rising due to competition, AI must serve a defined purpose rather than being a standalone strategy. Practical advice for professionals includes building relationships and contributing code to get noticed over simply applying to many jobs, which is often ineffective due to AI-driven screening processes, while internal examples show how teams can transform by teaching designers new skills like Git and cloud coding to become "AI-powered creators."
In conclusion, the most viable strategy for organizations facing the tech skills gap is a focused approach on upskilling current employees to multiply their decade-long experience with AI, potentially achieving tenfold productivity gains. This approach ensures that professionals can effectively guide AI tools rather than being replaced by them, turning potential threats into opportunities for growth and innovation. The webinar ends with a strong recommendation to review the *State of Tech Talent Report 2026* for further insights, reinforcing the message that workforce development is the defining competitive advantage in the evolving landscape of artificial intelligence.
Read the full video transcript
Hello everyone and welcome to today's
Linux Foundation webinar. I'm Hillilary
Carter, senior vice president of Linux
Foundation research and I'm delighted to
be your host today. We're diving
straight into one of the most critical
topics facing our industry and that is
the cape AI ability edge or the
capability edge. why workforce
upskilling is becoming the defining
competitive advantage in the AI era. So
over the past uh couple of years, the
dominant narrative in mainstream
headlines has been all about AI
replacing jobs uh shrinking teams and
making roles obsolete. But we have new
data from a recently released report,
the 2026 state of tech talent report,
which tells a remarkably different
story. AI is actually acting as a net
driver of job creation in IT. So the
real challenge for organizations uh
today is a lack of people, it's a gap in
capability. It's the challenge of
deploying AI safely, securely and at
scale and uh doing so across the entire
uh technology stack from platform
engineering to DevOps and cloudnative
infrastructure. Um I am uh I'm going to
stop sharing my screen now and I'm
delighted to be joined by uh our experts
and our of fellow collaborators in this
research project. Um a number of
partners uh helped us produce this
report. Uh firstly Linux Foundation
Education uh and our corporate sponsor
and partner in the study code. I'm
thrilled to be joined today by um Clyde
Cersad, Mumshad Manath, and Anna
Hermanson. And I'd like to take a moment
to ask each of our panelists to briefly
introduce themselves. Starting with you,
Clyde.
>> Right. Thanks, Hillary. A pleasure to be
here with everybody. This is obviously a
hot topic and on a lot of people's
minds. I head up the education team for
the past dozen or so years at LF and
it's really crazy to see just how
different the world looks now uh
[laughter] in terms of how tech is
embedded into our daily lives and how
it's impacting careers and career
trajectories. So looking forward to
today's discussion to maybe disabuse
some of the myths and get the focus on
where the real bottlenecks are.
>> Wonderful. Um, Mamshad,
>> thank you so much uh for having me
Hillary. Hey everyone, my name is
Mamshad Manad and I'm the founder and
CEO of CodeCloud. We are a hands-on
learning platform uh for DevOps,
Kubernetes, cloud native and and now AI
and uh we've been working with
enterprises and teams in helping them um
upskill engineers um in this uh era of
uh transformation. So, thank you so much
for having me. Looking forward to the uh
um the discussions.
Thanks Wshod Anna.
>> Thanks Hillary and thanks everyone for
being here. My name is Anna Hermanson.
I'm a senior researcher and ecosystem
manager at the Linux Foundation where I
support our endtoend uh project
management of our research projects and
I had the pleasure of working with Clyde
and Mumshad on this report tech talent.
Clyde and I also spoke on this at the
the Minneapolis summit earlier this
year. So, I'm excited to dive more into
the findings and have a discussion.
>> Terrific. Thanks, Anna. Um, all right,
then. Let's dig in. I'm going to return
to uh the screen where uh we were
featuring the report cover and uh give
folks an opportunity to uh scan the QR
code. Um this report really anchors our
discussion today. We have empirical data
um that uh was the result of a a global
survey that was fielded uh where
hundreds of qualified respondents
weighed in on um the realities facing uh
their hiring decisions, their talent
structure, their their organizational
needs in the face of um emerging trends
like AI. And uh I encourage you to
download the report uh read it and share
it. Um we also had the opportunity to
create uh regional versions of this
report. Uh so in addition to the global
report we have uh produced deep dives
into the European market and an addition
that also focuses on Japan. All three
reports are now available and have uh
some unique findings within each. Um so
setting the stage for a conversation are
a few of the takeaways from the global
report which I'll toggle over to now at
a very high level uh what's really
exciting is that AI in spite of the
headlines is not eating all of the IT
jobs. Um this was a phenomenon that
impacted only the largest organizations
uh where they had a net a negative
hiring effect of of minus 4%. But on
balance, um, uh, this was really great
news. And counter to these doom and
gloom headlines, the data shows a a
positive 31%
net hiring effect in it that is tied to
AI. So AI is not eating uh, the tech
jobs, it's actually creating them, and
that's more good news. However, it's not
all roses. Uh, security jumped as a
major concern. It was last place when we
conducted the study in 2024. It's now
the number one barrier to AI adoption.
Um, and additionally, there's a
capability gap, uh, the focus of this
discussion today, and it's prolific. It
affects 57% of organizations. Um, and so
what are organizations doing about
closing this gap? Uh, well, upskilling
is uh the favorite strategy. It's the
preferred strategy to close AI talent
gaps uh over hiring. Uh, so there is a
path forward. Uh so now I want to hear
from our panelists on uh some of these
data points and others from our study.
The first topic I want to talk about is
the real state of AI and IT jobs. I'm
going to begin with Clyde. Uh Clyde, the
reports showing a 31% net hiring effect
tied to AI and that runs counter to a
lot of the the headlines. So what is
actually driving that number?
>> Yeah, I think there two different
things, right? there is if you get up
every morning and read the popular press
and see what's in your feeds, the things
that make the news are the are the big
cutbacks, right? And there have been a
lot of those, especially at the biggest
tech companies. Uh although in
aggregate, if you look at their staffing
levels, they they've only really just
returned to staffing pre-COVID. So,
there was this huge staff up postco and
now they're sort of drawing down. And
that gets the news, right? you know,
5,000 people laid off, 10,000 people
laid off. What doesn't make the news is
the thousand small companies that hired
5 to 10 people a pop. But if you talk to
and I talked to a lot of folks who got
displaced from the larger tech companies
over the last you know 18 to 24 months
and what you see is a pattern where
they're pretty typically ending up
relatively quickly at another smaller
organization in a role that they find
interesting and fulfilling. And so I
think the a big part of the challenge
here is this disperate narrative between
the headlines that garner attention
which has tended to be for the last kind
of three years big layoffs, big
restructurings and uh really probably
you know is less about the freeing up
cash to invest in AI because you'd have
to fire a billion people to justify a
trillion dollars in in data center spend
and more about just kind of correcting
staffer levels at the biggest. And what
you see in the data is the real
aggregate underlying view which is
organizations as they are adopting these
technologies are finding that they need
better technical infrastructure,
revamped technical infrastructure, more
people paying attention to the systems,
how they're set up, how they're running,
how they're being secured, and that's
increasing the appetite for technical
talent um that is embedded and
understands how to run AI. inserting the
headline noise is you know look it's
it's undoubtedly true that there's been
a lot of displacement and that's always
you know rough on the individuals and
psychologically tricky but in aggregate
this has not been a story where we don't
need the technologists anymore this has
been a story where most organizations
are discovering they need more tech not
you know by the way not unlike what
happened when we went through the
cloudnative round and you know we
weren't going to need cis engineers
anymore um and so I think we're just
settling into this, you know,
new reality of what does it really play
out as? And what it plays out as is you
might automate a lot of your business
processes, but you're going to need
technical people running these systems,
training the business units, securing
them, scaling them, managing the cost of
of the spend. Um, and so I think this is
what this report to me really
highlighted was uh what's really
happening in a way that isn't flashy. uh
and how different that is from the
narrative of we're all going to lose our
jobs and the AI is going to just you
know uh take take over every single job
role.
>> Yeah, that's that's uh a relief I I
think to to many. Thanks Clyde. Um, next
Anna, I uh this question is for you and
it's about the the types of roles that
are accelerating fastest uh that the
report revealed and where we're seeing
growth whether that's at the entry level
uh as well or or concentrated at a more
senior or specialized roles. What can
you tell me about the types of roles um
in the market today?
Yeah. So the the report asked our survey
respondents to specify where these
hiring managers are seeing the most
growth and acceleration in in job
capacity and we found of course AI is
accelerating the need for AI specific
roles. Uh but we also found some growth
in software development in uh technical
management, IT operations, QA testing.
So the kind of the ecosystem around an
you know AI infrastructure and making
sure that AI infrastructure is
sustainable um secure and and
responsible. Um within our global report
we found that uh 29% of organizations
are actually increasing entry-level
positions. There is 22% that are
decreasing. So um you know 7% net
positive impact in entry- level
technical positions uh which is of
course a a good story for at a global
level um and about half are from that
are not changing their entry level uh um
hiring. So on the whole all of these
positions are increasing but uh you know
as as Clyde said there's that kind of
individual level decreases that are
happening. Um but yeah on an aggregate
we are seeing these types of roles
increasing. Um as we mentioned at the
top of the call we did do some deep
dives into Europe and Japan. And so just
to note that um in Europe we we also
found a net positive uh hiring effect
but at a smaller scale than the rest of
the world for all of these different
roles. And then um Europe was also the
only region where we found a net
negative entry-level hiring impact. So
um you know important to note that in
Europe we are seeing more pe more
organizations decreasing their entry
level than increasing. Um and then in
Japan we saw actually the reverse of
this. We're seeing a larger hiring
effect than the rest of the world. And
very few in fact very few organizations
are decreasing the workforce at all due
to AI. Um, and so just uh kind of a
thought about about that. I we found
this in our other research we did with
Meta on the workforce impacts of AI. And
so this is maybe not so much a job
displacement, but how are these jobs
transforming? How is AI restructuring
these roles? um you know our our former
chief economist Frank Nagel spoke about
the death of engineering being
exaggerated and how um these AI coding
tools are helping developers focus on
core work and you know Clyde and I have
spoken about how AI actually requires a
transformation of of developers to work
more with soft skills and business
skills on the human side of things. And
so um there is I think a very
interesting job transformation happening
where um developers may need to learn
newer skills or or a different side of
of their of their um craft. Uh but we're
not necessarily seeing a job
displacement by any means.
>> Yeah. Thanks Anna. I it was very
interesting when we looked at the Europe
report and as you mentioned it was the
only region where at the entry level
there was a negative impact and that
really shocked some of our European
colleagues. Uh Mirum who um leads uh a
lot of our community work in Europe
found that really unsettling. uh
especially in a region that has um over
the centuries embodied an an
apprentichip
uh type of culture and I think it's
critically important that uh that
continue um and that organizations in
Europe uh start to rethink their
entry-level hiring again uh so as to not
leave themselves a little short uh when
it comes uh when we look at what the the
landscape's going to be a 2 years from
now and I should say that Mirao wrote a
terrific blog on that port on that uh
point uh once the Europe report was uh
published which we can share as well. Uh
all right let's turn to another theme of
the report which is where the skills gap
actually are and my next question is for
Mumshad. Um, Mumshad, the data in our
report points to uh a full stack
readiness problem, not just an AI
specialization shortage. Um, from what
you see among leaders in enterprise
teams, where are the gaps the widest in
platform engineering uh in Kubernetes uh
skill sets or DevOps? What are you
seeing out there?
Yeah, it's it's very interesting um as
we see in the report and it's it's uh
very reflective of the state um
internally in our company uh as well as
uh the enterprises and other clients
that we work with and I I find it useful
to look at it in kind of three different
lenses. So this there's this first group
of people in the company who are the
individual contributors, the developers
who are using coding agents to build
applications, the um um you know the
non- tech people who are probably using
it to you know summarize documents and
you know uh generate marketing material
um you know do some finance reporting
around financing things like that. Um
and then there's the second group of
people who are uh those who are building
agents. So these are like core
developers uh who are building agents
internally um either for internal
customers or uh for external customers.
And then there's the third group of
people um who [clears throat] are kind
of quietly forgotten. And these are the
the group of people who are uh
responsible for building the
infrastructure, the systems, the
guardrails uh that make it safe for
everyone in the company to uh use AI and
to thrive with with AI. Now the the
numbers in the report state that like
every company like 97% of the company uh
of companies are organizations are
adopting AI. So there is there's u no
doubt in the uh I guess no doubt left in
in in how useful and effective uh the AI
tools are and how how they're improving
on a day-to-day basis. But what's really
happening is a say a developer um builds
an AI agent um takes it to the
leadership team, the management team and
presents it and it kind of goes in two
in two directions. Either um they the
the team likes it, the management team
likes it and they they want to adopt it
for the rest of the com uh you know the
rest of the organization or uh one one
of the other thing that we also see is
that the management team saying you need
to shut that thing down and delete the
code and never mention anything about
it. Right? Okay. So there there are two
of these categories of responses uh that
we see. Now if uh in in the former case
where the um solutions are adopted uh it
might be a really good demo but to get
it into a production state uh requires
uh it to go through a series of checks
and um you know uh audits and different
teams um reviewing how it is built. So
there's a security team who wants to
know how uh how it's built and what are
the what are the touch points endpoints
that it touches. U there's a finance
team asking about the costs uh of the
tokens that it's going to consume which
uh in in most cases is under projected
in the beginning while these agents are
built. Um and then uh the operations and
other teams wants to know uh who's going
to be impacted if this thing uh goes
wrong or you know if if this fails. Um
and and basically that's the pattern uh
underneath the report that uh the
report's numbers right so the 97% of
organizations are adopting AI and then
uh the largest capability gaps are AI uh
security and risk management that's at
57% AI operations and monitoring at 57%
cost optimization at 54% and then none
of these are AI or model related
problems these are all uh infrastructure
governance related problems and uh Um I
think uh the the biggest gap that we see
is really in the platform engineering uh
the infrastructure side of things where
uh there's really no training uh uh you
know or upscaling happening around how
these uh agents are going to be deployed
in production in in in the
organizations.
>> Great. Thank you uh for that insight sh
that it's a great segue to a question
that's come in in our Q&A.
Um and it's uh are university degrees
irrelevant now? Should I drop out of
college? Uh what does everybody have to
say about that? Anybody want to go
first?
>> I'll I'll go first on this one. Don't
drop out of college. Um
two reasons. One is uh although
employers might be saying they don't uh
give the same primacy to a college
education as they used to and that's
true and that shows up in the report
right that they're looking for things
like certifications the foundational
skills that you build there and
especially some of the people and soft
skills what people call durable skills
it's so much more critically important
now to be able to have those
communication skills to be able to deal
with conflict to be able to have
persuasion and that's a lot of what the
work you get done in colleges in group
projects and I think that is highly
underappreciated
uh and the second is you get this
broader perspective right so that you're
able to have a more integrative view of
things and and that's where humans add
value to AI right is you know AI is
exceptionally good at synthesizing
everything that's ever been written on a
particular topic it's not great about
finding novel connections about
intuiting people's uh perspective and
where their reservations might be and so
you You know, I think what's changed is
a degree on its own used to be
sufficient and that's no longer true.
Uh, and you know, to be fair, it is
harder to get a, you know, we had a long
period where you kind of finished, you
sent out your resumes, you got 15
offers, you cherrypicked which one you
wanted to go to, and that's not true. I
think the the reality if you're have
recently graduated from a computer
science type program is it's harder to
find a job. uh and in part because if
the same upskilling conversation,
nobody's looking for just a software dev
or just a back-end web developer cuz
everybody's expecting these more
integrated skill sets. And so, you know,
I think the answer is it's not or, it's
and like finish that degree and
[clears throat] make sure that you're
expanding your horizons and playing with
models and thinking about what the cost
structure looks like and thinking about
what, you know, platform engineering in
the age of AI might look like cuz, you
know, we recognize those things aren't
yet fully represented in university
degree curriculum. So, you know, it's a
baby and bath water problem, right? is
it's no longer enough by itself, but
that doesn't mean that you shouldn't
finish it. It does mean you should be
focused on building a much broader
portfolio of skills and coverage than
than you frankly have had to the past 20
years.
>> Yeah, well said. Any other uh thoughts
on the value of college and university?
Yeah, just to add on to uh Clyde's
point, um I think one of the things that
we keep talking about when we talk about
AI is the foundational knowledge that
people need uh before using AI so that
uh with AI you can kind of multiply
um your your craft uh so to call it,
right? And and one one example that I
keep going back to is um say like a
graphic design. Um if you had to create
a logo for a company or or graphic
assets for for a company, it's very easy
these days to get AI to create it. And
AI is going to create like 10 20
hundreds of uh images and samples that
you need. But if you're not if you're
not from that, if you haven't done a
degree in graphic design, if you don't
know how the the shadows work or the the
color gradients work or or the rounded
corner, you know, um the corn corner
roundedness work and and um how they
kind of relate to different values or or
how the brand is projected based on all
of these combinations. uh if you don't
have that knowledge uh you will not be
able to pick the right uh graphics or
assets or you won't be able to use AI to
build the right uh assets uh and and an
experienced graphic designer would be
able to use uh AI to uh kind of 10x
their productivity and um get AI to do
80% of the work while they can still uh
pitch in to finish that remaining 20%.
But in order to do that that
foundational knowledge is very important
and the same goes for everything right
uh with white coding um one of the
reasons why people get stuck after that
initial um u phase of white coding a
project is because they don't know how
to when it when the codebase gets
larger. uh they now don't have the
foundational knowledge needed to uh to
expand on it to build uh the right test
cases to host it um in a scalable manner
and all of those come from having those
very foundational knowledge knowledge
and and you get a lot of that um in
college and so yeah I would I would echo
what Clyde said on not dropping out of
college.
>> Awesome. uh and I'll allow you to chime
in on that, but I also want to hear from
you on how we went about measuring
understaffing uh within the report and
the different domains. Uh so um what are
your thoughts on on both of those items?
>> Sure. Yeah, the uh maybe just to start
with the underst staffing um and then a
bit into credentiing and and skills
development in different pathways. I
think the so our survey we asked our
participants um how underststaffed they
are what level of underst staffing
they're experiencing across different
domains of course a IML as well as cyber
security uh cloud native phops those
kind of domains and um I would say that
you know we found all of these domains
they are they are experiencing
underststaffing um although compared to
last year's report we found that this
understaffing nothing was actually um
decreasing from from last year by about
an average of 14% and so um that was
good news but then in the next follow-up
questions we talk about the capability
gap and we see that this capability gap
is in fact increasing across these
similar domains um AI operations cost
optimization so um despite being less
understaffed the capability gap is
widening and I think that
thinking about what that what that could
mean. The you know we look at the depth
of transformation happening and the
possibilities of of integrating AI into
the you know into business processes.
these are expanding and that presumably
makes the capability gap much larger.
And on this on the flip side, fewer
people have that expertise to
substantially transform these processes.
And so um you know I thinking thinking
more about how to upskill or how to how
to be a relevant resource in this in
this uh market that uh we find that on
you know on one side institutional
knowledge is incredibly essential in
this in this state where these processes
are being transformed and knowing how to
best transform them is critical. Um
which as as I said that makes up
upskilling very valuable. Um but then at
the same time, you know, there are we do
need this junior on-ramp as we we spoke
about a little earlier. Um and so that
um you know, engaging with a university
degree or maybe another form of ed
education to learn how to develop the
skill to to have this kind of just in
time portfolio as things transform so
quickly. um is is really relevant to to
this market where the capability gap is
so wide and there's such a critical need
for individuals that can that can build
out not just an you know using an AI
tool but building out this entire
infrastructure.
>> Excellent. And you you two think
everybody should stay in college, right?
>> I I I mean I loved school so um I'm a
researcher. I'm a nerd, but I loved
school. And I think it's a critical,
you know, it's you learn a lot of
critical soft skills. You you learn how
to learn. I think it's, you know, you
get a a bigger picture of what's going
on besides laser focusing on on a
credential um or a training course. So,
yes, of course, I if you can if you can
get there to that point, definitely
stick with it.
>> Yeah. Yeah. And I would also say the
relationships that were built during uh
both of my degree experiences were were
critical to my career success. So soft
skills relationships and the uh academic
credentiing. Um I I'm seeing lots of
great activity in the Q&A, but it is
time for our first polling question. So
um keep your eyes on the screen for our
poll number one. We want to know what
the biggest barrier to AI adoption is at
your organization today. Uh the response
options or security concerns, lack of
skilled talent, budget constraints,
unclear ROI, tough to pick one. Wow.
Leadership buyin, um reliability and
hallucinations. The biggest barrier.
This is tough.
We as panelists cannot vote in this. It
would be tough if I had to.
>> [laughter]
>> I tried to actually. Yeah, I didn't know
I couldn't.
>> And we'll just wait a minute for uh the
results to come in.
A lot of these issues are prompting all
kinds of different uh initiatives
certainly across the Linux Foundation
around ROI and and AI with the launch of
the tokconomics uh foundation. Uh, of
course, uh, our education, uh, community
helps address the the the skilling,
um, OpenSSF with security concerns, but
yeah, it's hard it's hard to pick one.
All right, here.
What do you think of those results?
Security concerns validating exactly
what our survey data said in the report.
Not not overly surprising given all the
news recently, right, about bots
behaving badly. I feel like that could
be like a back in the day it would have
been an MTV series. Um, it's it's top of
mind for people, right? Just how and and
I see a question from Michael in the Q&A
as well about um I like how it's phrased
developers of models are having
difficulty controlling what the AI is
capable of security securely doing. Uh I
think this speaks to this practice that
is needed around security around
uh you can't just set your guard rails
at the start and then assume that you
know it's on autopilot right so there is
a structural need for just um maybe
paranoia is too strong a word but you
have to really be checking what your
agents are doing right after the recent
example where the open AI system broke
out and hacked hugging face. The
anthropic people then went back and did
an audit of their internal evaluations
and found a whole bunch of of hacks and
attempted hacks, which begs the
question, why would they check in the
whole time to see what these systems are
doing, right? And so I think the whole
practice of uh trust but verify is sort
of an aha for people because we're so
used to deterministic systems, right?
Like when you build your Kubernetes
orchestrator and you set, you know, your
health charts correctly, you kind of set
it and forget it and you move on to
something else. With AI, you have to
have this recursive process of just
evaluating and evaluating and figuring
out what went wrong and course
correcting and then getting input from
the business. And so it just becomes a
much more comprehensive way of living
and it becomes a much more um sort of
team effort to think about all the
different ways in which security matters
and in which you know mom was talking
about vibe coding where you know I've
heard multiple stories of people vibe
coding where the bot says can I have
root access like sure and they have no
idea what root access is they just think
it's a road bump along the way to get
the thing vibe coded right so it's just
they we're beginning to realize realize
that uh you know it's all fun until
someone loses an eye. It just we're
starting to see the spiky bit of of you
know what happens if you just let
unfettered access run free.
>> Uh anybody else want to weigh in on the
poll or the theme?
>> My grandmother would say the chickens
have come home to roost.
[laughter]
>> All right. Well, let's carry on uh with
a new theme which is about security and
very fittingly it was the number one
barrier to AI adoption. Why security
became the number one barrier uh almost
overnight? Um so for
mom let's start with you um security
jumped uh what's changed?
So the the way I would like to think
about security is and and one of the
sharpest uh framings of security in AI
that I've seen is from um uh somebody
named Simon Wilson who is a person who
coined the term prompt injection and um
he called this uh lethal trifecta. So
basically you're giving your AI agent
access to um external uh external access
to browse um you know to do research and
browse uh websites. Um and the same
agent has access to your internal
database and it also has access to uh
communicate externally be it sending out
an email or or a WhatsApp message or or
a message uh in some some form. with the
a with these three uh accesses, the
agent now becomes lethal, right? So, it
can read uh a page during its research
and there's probably um a white text on
a white background that is not visible
to the human eye, but when it when the
page is red, says it's some sort of a
prompt injected attack where it says um
read something from the database and
send it to this email. uh takes it takes
that instruction, reads the database,
queries the database and uses the
external access to send out an email. Uh
one classical example that's that's and
and that makes the agent um lethal. Uh
with the uh um the advent of MCPs and
ways to connect to almost anything you
want and in this and and in our internal
stack uh be BigQuery or u Slack or any
of our internal systems. um this becomes
uh an even more um lethal um because now
you're enabling anybody to build an
agent and provided like these sets of
MCP servers go ahead and use whatever
you want um and just even if it's not by
design um during the activity the AI
agent is able to kind of form this
lethal trifecta on its own. Now the
thing is in the past we had like similar
things with SQL like SQL injection but
we were able to mitigate that by kind of
separating the query and the the the p
the parameters come and and kind of
coding it in saying these are coming
from two different paths and so
deterministically we were able to kind
of separate that uh but now it's um in
in this uh phase it's it's kind of uh
because AI is uh probabilistic um this
becomes
way more harder and it's now um every
everything from the security perspective
that we've built kind of the past uh
decade we've we've never been ready for
this phase like like maybe 3 four years
back before Chad GBT nobody even knew
like that there was this whole AI uh
revolution coming and then we need to be
prepared uh for security like Chad GPT
just came people just started using it
cloud code came everybody just started
using it like there's no nobody stopped
to think, hey, wait, let's talk about
security first, think about it, and then
adopt this. Like people just went just
went crazy. And um I think that's
probably that's why all the fear and
that's why that's what the report
reflects.
>> Yeah. Time for some guard rails and some
processes. Um, Clyde,
>> yeah, you know, look, it's important,
but I
uh
I think it's also a question of where we
are in the maturity cycle. So, I was
using the analogy recently of uh I look
at my kids now and they're 16 and 18 and
they're beginning to have some good
judgment and they're beginning to
understand sort of holistically about
the world. And I think back to when they
were doing um soccer as like six and
eight year olds and I feel like we're at
that stage, you know, prompt
engineering. Oh, let's all run and think
about prompt engineering. Oh, agentic.
Let's all run and worry about agentic.
Oh, security. Let's all run. And of
course, the answer is all. You have to
do all of it. And by the way, the next
one that is beginning to get traction
now is cost. And so we just launched the
tokconomics foundation thinking about oh
my gosh there's a bill and how big is it
and what did we spend that on and so you
know I think as we go through this
process we're maturing and we're
learning about all the different
components and they're each taking a
turn in the spotlight. Uh, and we're
going to have to get to a place like we
got to with cloud native where we're
able to walk on chew gum and think about
security and think about cost and think
about scalability and think about, you
know, what's the right, you know,
verifiable rewards with the agent isn't
so motivated it starts breaking out of
sandboxes and and and and so that's why
I think this upscaling piece is so
critically important, right? Is this
this old mindset of hey, I'm a DB
administrator and I here sit there and I
administrate the database all day long.
Leave me alone. like that world doesn't
exist, right? And I think to go back to
something Anna said about, you know,
it's more important now than ever to to
learn how to learn and to realize that
every single one of us like the premium
on continuing to learn and adapt is just
rising and that's a little uncomfortable
cuz we used to be able to get to a point
where like, hey, you know, I'm the sort
of, you know, king of the hill here. I
know everything there is to know about
front-end web design.
>> So, I think security is important. It it
just it's one of many things that's
going to be important and we're going to
have to all get cross-killed on this
stuff, right? We we can't just be naive
and say, oh, you know, cso is going to
come in and clean this up.
It's going to have to be much more
collaborative, much more integrative.
>> So, how do teams uh get started and what
practical first steps do they really
need to take? Um, Mum Shad, do you have
some thoughts on this question?
>> Yeah. Um I guess like continuing from my
uh the the lethal trifactor example that
I shared earlier, I think the first
thing would be to really start putting
in some guardrails and maybe if if uh
there are agents built without
guardrails and maybe the first thing
would be to audit them and identify
areas of uh uh lethal factors that are
built in place. So uh agents that have
access that have been given access to a
lot of things. So I think that will be
the first step in in doing an inventory
and identifying what agents are built
and what accesses they have. Um and um
there are a lot of uh projects that have
come up recently that are uh going
towards uh making agents safe in the
first place. And of course the models uh
get safer like for example I think the
one of the things they mentioned about
Opus 4.5 is that uh it it it can now um
it now does not respond too much to
prompt engineering by default. So even
if if someone accidentally injects uh a
prompt engineer text into its prompt
it's it has the ability to detect that
and not uh kind of respond to that or
ignore that. Um there are other
solutions like model armor uh you know
from Google cloud that that we use for
our projects uh where all the requests
to the LLM providers to AI kind of go
through this armor and this armor has
the um logics in place and the the
deterministic guardrails in place to
identify uh if there's anything wrong
with these requests that are going in as
well as if something is searched on the
internet is coming back down that to
goes through this model armor and where
uh there's a filtering level happening.
So this is all on the AI side and agent
side. But if you go outside of that back
to the infrastructure and the the
environment,
a lot of things that we have done in the
past couple of decades around security
still applies like all the fun security
fundamentals uh still apply. For
example, the access that we give to AI
agents either through a service account
or uh a token um that needs to be
reviewed and it needs to have just
enough access to do what it needs to do
like the minimum uh minimum level of
access. So rolebased access control all
of those security fundamentals that
we've built for the rest of the
infrastructure still applies here. Um so
yeah I mean that's that's what I would
say would be uh the first step in moving
towards security in AI.
>> Awesome. Uh I want to touch on um the
approach to how we close the AI
capability gap and the the calculus
whether to hire or upskill. uh our
report revealed that upskilling is the
preferred
um uh pathway. Uh Clyde, what what's
your take on that? Why do you think uh
institutional knowledge is is really uh
critical and and why organizations are
choosing upskilling as a pathway? Yeah,
I think you know this is one of these
things where uh
many I mean maybe even most
organizations when they first started
their AI journeys they picked things
that were pretty simple. They picked
things that were already cloudnative
infrastructure behind them and then they
got all excited about, oh wow, look at
this, you know, [laughter] I I can take
this new thing and put it into, you
know, an agentic workflow. And what they
started to discover then as they went
back towards sort of the real business
and the core business is, man, there's
all these like obstacles and
difficulties. And when you get to that
place, the business context is so
critically important. You know, my my
favorite anecdote of all of this is I
think it was last year, one of the fast
food um companies in the US implemented
an AI powered uh order taker for the
drive-through lane. And so, you know,
you go, you speak, it does a natural
English uh you know, interpretation, it
processes your order. And it all sounded
great and you know real time dispatch of
the kitchen and but except it turned out
that the people who built it had never
worked on a drive-through line in their
lives. And when it sent the order to the
kitchen, there was no concept of
somebody might change their mind. And of
course, if you've ever been through a
drive-thru line, it's very frustrating
how people can spend 10 minutes giving
an order. Uh and it was just a pure lack
of business context, right? that you
know even after you've said yes that's
my order and you begin to drive your car
off you still then slap the brakes and
say oh no and add fries and add a drink
and add something else and you I think
it's a it's a simplistic example but it
just captures in in a very direct way
how important the business context is is
to why do we do things the way we do why
do we not do certain things hey things
that work in this jurisdiction don't
work in the other jurisdiction
uh there was a famous example here uh
last month or a couple months ago about
the meltdown with Starbucks in Korea
because they put some copy in the
marketing campaign that like trod over
some like horrible sensitivities. Uh and
often you come back to the same thing,
right, which is didn't somebody know
better? Didn't somebody know not to do
this? And I think we're starting to
discover that they uh
it's just so important, right? You know
I uh
there's a great statue in Rome by the
scenini and it's a uh it's a carving of
an elephant with an obelisk on its back
and the concept was that
uh wisdom should knowledge should always
be supported by wisdom right so the
obelisk is is is the knowledge which is
kind of like the LLMs they've read
everything and the elephant is the
wisdom And I feel like that's what we're
seeing, right? Is the wisdom of the
people who've been there, who
understand, who understand the
suppliers, who understand the customers.
And so the challenge for us is okay, we
need to keep that wisdom in house. How
do we then upskill that wisdom so it's
comfortable thinking about what an
agentic workflow looks like? So that
it's comfortable thinking about what a
non-deterministic,
you know, algorithmdriven
um uh LLM output model might look like.
And that's why it's become so critical,
right? Is well, we we can only do this
well with the people we have who
understand the business contexts, who
understand, you know, the compliance,
etc., etc. And I think it still really
is. I think we're just going to keep
learning that lesson over and over
again. And it's going to be challenging
because it's going to require us to
start doing upskilling into technical
topics for people who aren't necessarily
technical to begin with. And it's going
to require us doing upskilling of
understanding the business side of
things from people who've been very
technical and have been saying hey just
send me a spec doc like I don't want to
talk to you give me the spec and then
you know we are we're off to the races
and so that idea of building on what the
business knows bringing more people in
and upskilling can mean different things
right upskilling can mean you know
communication skills for an engineer who
likes his stuff written down and shoved
slid under the door um And it's just you
know this is going to be the reality I
think for the next 5 10 years is how do
we take advantage of all the human
knowledge get that human capital
comfortable working with these new sets
of tools and collaborating on these new
tools
>> wisdom as a strategic asset. Mumshad
quickly before we go to our our second
poll question from your point of view uh
how do we effectively upskill in
practice?
Yeah, just [clears throat] to echo uh
what Clyde mentioned, I think um
it isn't like you could think of
replacing your engineer who's been with
the company for say 10 years with all
that institutional knowledge and uh get
uh with someone replace that person with
someone who has like 10 years of
experience in AI, right? that that's not
happening because like when it comes to
AI everybody is new like it's every
everybody's absolutely new like the max
you can find is maybe three four years
experience even if it's somebody who's
just picked up uh open AI the moment
chip came out it's it's just been like
three or four years so when it comes to
AI one of the things to understand is
everybody is know the entire wide world
is is except for those who have like uh
who are veterans who are who who've
built the models themselves who who or
into machine learning and things like
that. Except for those category of
people, everyone else is is uh uh new to
AI. And I think one of the uh the the
easier approach is to simply replace uh
simply uh upskill the existing engineers
who have the institutional knowledge uh
and add AI to their skill set and help
them learn um help them uh you know
become more efficient uh and and in in
their in their practices. So and and one
example that I'd like to give is our own
example from from our own team. So we
have um if you've seen our courses, we
uh we visualize a lot using a PowerPoint
and things like that and we have a prop
designers in the team. We have video
editors and these are people who have no
tech skills at all. They are mostly just
uh editors and designers and uh uh it
takes a lot of time for us to build uh
our slides. um you know and and then
we've been spending a lot of time
building these out in the past couple of
years and when AI came we started
experimenting with a lot of tools and
after like almost a year or two of
experimentation we eventually built a
tool set uh a course authoring tool set
fully with AI um when the uh AI models
evolved into generating really good UIs
we were able to uh capitalize on that
and build a set of tools that kind of
replaced our PowerPoint and After
Effects kind of Asia kind of tools
entirely. So overnight we kind of
stopped using PowerPoint and uh Camtasia
for slides and instead we started uh
going with the AI tools that now started
generating much better visuals and much
better slides. Um now uh the and and one
of the questions I got from the team was
like what do we do now? You know we our
experience has been on PowerPoint and
and uh video editing tools like what's
our fate? So at that one that at that
point I realized that there's been a big
misconception right? So I told him like
your experience has not been on
PowerPoint. Like the the the past seven
years you helped me create all these
courses. Your real skill has been uh
creating awesome educational videos.
That's your real skill. Like you know
how to take a concept, simplify it and
make a really good video out of it. You
know how to take create a lab and you
know how to combine these two to build
great learning experience. and you know
how to combine a lot of those to create
a course and combine a lot of courses to
create learning paths that take students
from being an absolute beginner to an
expert that is your experience and
PowerPoint and video editing skills
these are just byproducts these are
tools that you just learned along the
way so we kind of uh converted them to
AI powered engineers by uh teaching them
git and teaching them Linux and uh cloud
code and now they use those tools to
create the uh the videos, but because
they have they know what a good video
is, they're able to use that skill with
AI to create even better videos faster
um than what they did before. And so now
they've kind of transformed into these
AI powered um video creators or or or
designers. And I think that is what
everybody needs to know because people
often ask me, my students ask me like is
AI going to replace Kubernetes or is AI
going to replace Docker? And what I tell
them is the uh what you've learned these
past uh decades working in IT is not
Kubernetes or Docker like you know
something might replace Kubernetes in
the future. So your the the cube cuddle
command line utility is not what you
learn. What you learn is how a software
goes from a developer how it gets built
and how it gets tested and how it gets
deployed and how it gets served to
millions of users at scale. And this
whole system is what you've learned and
uh individual tools here and there will
get replaced and that is something
you'll just have to upskill yourself. Uh
so I think once people understand that
um then things become very easy because
now you just need to add AI to your
skill set uh and then you can 10x your
productivity. So if you if you don't
know anything originally and you add AI
to that so you you know 0 times AI is
zero but like your craft that you build
over the past decade you multiply that
with AI and then you kind of get an
engineer who can't be replaced or who
can't be automated right so yeah I can
that's that's kind of my long-winded
answer to to the question
>> nice it's a holistic approach certainly
and uh it's got a lot of legs uh let's
um pull up our second poll question and
we're getting close to the top of the
hour. See if organizations agree about
uh what their primary uh uh approach to
closing the tech skills gap is
upskilling staff hiring new talent both
equally or they're not currently
addressing it.
>> Hey Hillary, while we wait for those
answers to come in, there's one question
that was posted in the chat that I
wanted to address. please.
>> And it was somebody expressing
frustration about uh applying for a ton
of jobs and getting screened out by the
AI. And I think that resonates heavily
with me and with you know a lot of
people because it is it does feel like
um
uh just this rising tide of more AI
applications and then more AI tools
reading the applications. And it reminds
me that you know the one thing I tell
especially college graduates now is
uh
your odds of getting a job are not a
function of how many places you apply
to. It's a function of where do you
invest time to build relationships.
And I'll tell you firsthand, the last
two or three roles we've had within the
education team at LF, like this, the
pile of applications was so
overwhelming,
the only ones we really were able to
spend time on were the referrals.
And uh I know that's uncomfortable news
for folks who felt like, well, I got the
degree like why, you know, why isn't
that demonstrated capability enough? And
I think the reality is I'm sorry it's
just kind of not you know in this new
world where there's you know AI wars on
both the applicant side and the and the
reviewer side the more you invest in
building relationships the more you
invest in volunteering so you can
connect with the people in the right
industry in sending code commits
upstream into projects that you're
interested in so that you can you know
you know get onto somebody's radar. Uh
it's funny, right? Like the human
connection piece is getting more
important because the act of applying
has become so trivially simple. And uh I
think that's what we're going to find.
It's just it's just getting a foot in
the door is not going to be about what
what your resume says. The resume is
unnecessary but not sufficient
condition.
>> Yeah. Experientially I would agree in in
past hires that I've made. Uh so our
results are in and upskilling is the
approach for uh folks that are
addressing the skills gap. Um 27% not
currently addressing it. Some hiring
still taking place out there. That's
that's also good. Um yeah, any comments
on the poll results?
>> Scary to not be addressing it at all.
[laughter]
just
organizations have got to take this
seriously.
>> What about follow on uh thoughts? Um
Anna, any comments on what Clyde had to
say about relationships and career
pathways or relationships as a skill
set?
Yeah, I think the
I think I mean my experience, you know,
I I started at this job because I had
built a relationship with you, Hillary,
in a previous role. And so I think that
um it's always kind of been, you know,
get yourself out there, get networking,
um meet people, go to informational
interviews, and um you know, often a
cold call application,
but it's not always the case that that
will work if you don't also make the
effort to to try and meet someone, reach
out to them. So I think that's always
been the case. And I um you know I've
yet to to go through a job application
process in this new kind of AI
generative AI age. And so um I can't
entirely speak to that personally, but
um I think there's that has always been
the case. I would imagine it's as as the
question the person asking the question
experienced it's increased with um you
know with with AI tools wiping out an
application quite quickly. But um yeah,
I would I would imagine the that benefit
of face to face interaction and having
that that kind of human side to your
application becomes even more critical
in this in this context.
>> Thanks Hannah. There's a great question
which I think is worth touching on and
it's about the executive culture of
handling AI buzzwords and getting
executive buyin. didn't poll very highly
in our first poll, but I think it's
hugely relevant. Any comments on on that
point?
>> Yeah, I think this is not new, right?
This is like the gardener hype cycle
version 64.
You know, keep asking the question why,
right? What is it we're trying to
achieve, right? Is it that we are trying
to expand into new markets and trying to
grow revenue? Are we trying to get
deeper connections with existing
customers, bring new customers in? Are
we trying to get cost out a certain part
of supply chain? You know, there's
always this sort of, you know, I call it
the pixie dust fallacy, right? Oh, we'll
sprinkle some Kubernetes and then
wonderful things will happen and now
it's we'll sprinkle AI. And so, uh,
asking why, asking for clarity of
direction on what it is you think is
going to happen if we're all doing, um,
you know,
reinforcement learning with verifiable
rewards and somebody heard about RLVR
[laughter] on on a podcast so that we so
that you can get some clarity and some
alignment about what it is. You know,
what do we think? What are we trying to
aim at? What does success look like?
Because do more AI is not a strategy.
Yeah, agree. And I think I think uh it's
also driven by a lot of fear of missing
out, right? FOMO and um
um there there there's also I mean there
are things that you can do with AI that
that you should uh because it's also
going to a kind of uh it it will also
become one of the expectations from um
the users on on having some sort of a a
an easy chatbot that you can chat with
just to solve your problems like I I
guess you know very soon all that would
be like the minimal expectation from any
platform where you don't really have to
wait uh days to get your question
answered by the support agent instead
like an AI chatbot is supposed to be
able to help you in like 5 minutes,
right? I'm I'm I'm guessing uh very soon
that would be the norm. So there are
things that uh I guess um grows from uh
the users point of view as an
expectation which we you know we do want
to uh build that on the on the platforms
but at the same time a lot of others
could also be could just be driven by
the you know fear of missing out or fear
of competition um using AI to lead and I
guess that's kind of the uh other angle
of it that we we could look at to
understand why um why that's happening.
>> Well, this has been an amazing
discussion. Uh we are uh at the top of
the hour and I want to thank uh Clyde,
Mumshot, and Anna and all of you who've
joined our webinar today for the
terrific questions. We'll uh uh take a
look at any of the questions that came
in and do our very best to answer them
um after uh after the webinar closes.
But just a reminder to please uh do uh
uh check out our research report, the
state of tech talent report 2026. Thank
you all so very much for joining us. Uh
please reach out to um ourselves at LF
Research, LF Education or Mumshad at
CodeCloud and uh stay in touch. Good
luck with your training and upskilling
and uh thanks everybody for joining us.
>> Thank you so much everybody.
>> Thank you. Thank you so much to our
speakers for your time today and thank
you everyone for joining us. As a quick
reminder, this recording will be on the
Linux Foundation's YouTube page later
today. We hope you join us for future
webinars. Have a wonderful day.